<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-nmop-network-anomaly-architecture" target="https://datatracker.ietf.org/doc/html/draft-ietf-nmop-network-anomaly-architecture-06">
   <front>
      <title>A Framework for a Network Anomaly Detection Architecture</title>
      <author initials="T." surname="Graf" fullname="Thomas Graf">
         <organization>Swisscom</organization>
      </author>
      <author initials="W." surname="Du" fullname="Wanting Du">
         <organization>Swisscom</organization>
      </author>
      <author initials="P." surname="Francois" fullname="Pierre Francois">
         <organization>INSA-Lyon</organization>
      </author>
      <author initials="A. H." surname="Feng" fullname="Alex Huang Feng">
         <organization>INSA-Lyon</organization>
      </author>
      <date month="November" day="21" year="2025" />
      <abstract>
	 <t>   This document describes the motivation and architecture of a Network
   Anomaly Detection Framework and the relationship to other documents
   describing network Symptom semantics and network incident lifecycle.

   The described architecture for detecting IP network service
   interruption is designed to be generic applicable and extensible.
   Different applications are described and examples are referenced with
   open-source running code.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-nmop-network-anomaly-architecture-06" />
   
</reference>
